Legal
Report abuse or a suspected breach
Use this page if you think someone misused IMECore, accessed a file they should not have, or exposed personal health information. We follow the same steps every time.
Report a privacy or security issue
Email security@imecore.com for security issues such as unauthorized access or a suspected system compromise.
Email privacy@imecore.com for privacy issues such as a wrong recipient or a concern about how information was used.
What to tell us
- Your name, organization, and how to reach you
- Workspace name and, if you know it, the case ID
- Date, time, and what you observed
- Who was affected, if you know
- Whether the information is still exposed
Do not send sensitive health information by email unless you must to make the report. If you do, mark the message as confidential and we will move it into the case file and delete the copy in mail.
What we do
What happens after you report
The runbook in docs/16-breach-runbook.md sets the five steps. Every report follows them. The strictest deadline among PIPEDA, BC PIPA, and FOIPPA controls.
- Confirm. We verify whether personal information — name, DOB, PHN, claim number, medical records, exam findings, report content — was accessed, stolen, lost, or disclosed without authorization and whether it is still accessible to the unauthorized party.
- Contain. The decision-maker is engineering on-call for a platform breach, the workspace admin for an account breach, or the CEO or Privacy Officer if multiple workspaces or PHI are involved. We revoke the access, isolate the resource without deleting evidence, preserve the audit log, and notify the workspace admin.
- Assess. One owner gathers the facts: what data classes, which claimants, how many, and whether there is a real risk of significant harm. We cross-reference the audit log — actorUserId, action, targetType, targetId, metaJson, createdAt — and the affected case tables. If the answer is maybe, we treat it as yes and consult counsel within 24 hours. FOIPPA cases involving WorkSafeBC or ICBC require notice to the OIPC without unreasonable delay even while the assessment is open.
- Notify. The CEO or Privacy Officer decides whether the risk bar is met. If they are unreachable, the Engineering Lead decides and defaults to notifying. We notify affected individuals, the OPC where PIPEDA applies, the OIPC BC where PIPA or FOIPPA applies, the client per the service agreement, and the insurer. The shortest internal deadline controls.
- Record. We keep a written record of every breach, notified or not, for 24 months as PIPEDA requires. The record goes outside the application store so it survives a platform breach. The OPC and the OIPC may ask for it.
Templates
Notices we use
For the affected person
One sentence on what happened, the data classes involved, what we did to contain it, what the person can do now, and how to reach the Privacy Officer at privacy@imecore.com. See the runbook for the full template.
For the regulator
What happened, when, how we found it, which personal information was involved, how many persons are affected, the circumstances, containment actions with timestamps, notice to persons, steps to prevent recurrence, and the Privacy Officer contact. The runbook carries the draft.
OPC: https://www.priv.gc.ca/en/privacy-topics/privacy-breaches/ — OIPC BC: https://www.oipc.bc.ca/report-a-breach/
Other reports
Abuse that is not a privacy breach
Use the same addresses to report spam, harassment, fraudulent use of a workspace, or a violation of the terms of service. We will triage the report, limit access where needed, and tell the workspace admin what we found.
If you are the subject of harassment or a threat made through IMECore, contact local emergency services first if you are at risk, then email us.
Related
Where this duty lives
The runbook
The operational runbook is the breach-response runbook. It is version 1 and it says to confirm deadlines with counsel before use. We provide it on request.
The DPA
The signed DPA sets breach-notification duties between IMECore and the workspace, including any shorter internal notice. See the DPA summary.
FAQ
Questions about reports
What should I include in the report?
The workspace name, the case or user affected if you know it, the date and time you noticed it, what you saw, and how to reach you. Add screenshots only if they help and they do not expose health information further.
Will you tell me what you found?
We will confirm receipt within one business day and share what we can without exposing another person's information. Where the law requires notice to affected persons or to the regulator, the agreement and the runbook set who notifies and when.
Need to report something now?
Write to security@imecore.com or privacy@imecore.com. We confirm receipt within one business day.